VulnerabilityModified
CVE-2018-9840
The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.
MEDIUM 6.8EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Affected
- signal/signal
- Source
- cve@mitre.org
References
- http://nint.en.do/Signal-Bypass-Screen-locker.phpBroken Link, Third Party Advisory
- https://github.com/signalapp/Signal-iOS/commit/018a35df7b42b4941cb4dfc9f462b37c3fafd9e9Patch, Third Party Advisory
- https://github.com/signalapp/Signal-iOS/commits/release/2.23.2Issue Tracking, Patch, Third Party Advisory
- http://nint.en.do/Signal-Bypass-Screen-locker.phpBroken Link, Third Party Advisory
- https://github.com/signalapp/Signal-iOS/commit/018a35df7b42b4941cb4dfc9f462b37c3fafd9e9Patch, Third Party Advisory
- https://github.com/signalapp/Signal-iOS/commits/release/2.23.2Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.